Show filters
137 Total Results
Displaying 11-20 of 137
Sort by:
Attacker Value
Unknown

CVE-2024-2354

Disclosure Date: March 10, 2024 (last updated April 01, 2024)
A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of the argument id leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-22293

Disclosure Date: January 31, 2024 (last updated February 07, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrea Tarantini BP Profile Search allows Reflected XSS.This issue affects BP Profile Search: from n/a through 5.5.
Attacker Value
Unknown

CVE-2023-46887

Disclosure Date: November 29, 2023 (last updated December 06, 2023)
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
Attacker Value
Unknown

CVE-2023-46886

Disclosure Date: November 29, 2023 (last updated December 06, 2023)
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read.
Attacker Value
Unknown

CVE-2023-48017

Disclosure Date: November 18, 2023 (last updated November 25, 2023)
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.
Attacker Value
Unknown

CVE-2023-32123

Disclosure Date: November 13, 2023 (last updated June 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Dream-Theme The7 allows Stored XSS.This issue affects The7: from n/a through 11.7.3.
Attacker Value
Unknown

CVE-2023-48063

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
Attacker Value
Unknown

CVE-2023-48060

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
Attacker Value
Unknown

CVE-2023-48058

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
Attacker Value
Unknown

CVE-2023-45797

Disclosure Date: October 30, 2023 (last updated November 04, 2023)
A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code.